Source: Daniel Rubino / Windows Central
Cybercriminal group Lapsus$ has made quite a name for itself in a short amount of time, staging attacks against NVIDIA, Samsung, and others wherein it secures sensitive data then threatens to go public with it. And, just as it teased it would do to Microsoft, it has.
On Monday, March 21, 2022, following a brief hint that it had Microsoft goods to share, it dumped 37GB worth of files onto the web, including 90% of Bing’s source code and 45% of Cortana’s. Experts were confident the files were authentic Microsoft property, and now the company itself has confirmed their theories. However, the Windows 11 maker claimed it only observed a single compromised account with limited access, and that source code leaks don’t mean much in the way of security in this instance.
Furthermore, Microsoft made sure to note that “no customer code or data was involved” and claimed that Lapsus$’s public data dump backfired by alerting Microsoft to the threat, allowing them to cut short the cybercriminal operation.
When it comes to Microsoft’s security recommendations for combatting Lapsus$, it touted multifactor authentication (MFA), even though it admitted Lapsus$ works to sniff out gaps and weaknesses in MFA. It also recommended giving employees a refresher on social engineering strategies and and reminded orgs to be aware that the group likes to monitor “incident response communications,” meaning channels with those comms need to be secure.
We may earn a commission for purchases using our links. Learn more.